Privacy Policy

Privacy Policy

Privacy Policy

View Previous Versions

Flitto Inc. (hereinafter the "Company") processes personal information lawfully and manages it safely in compliance with the requirements of the Personal Information Protection Act (「개인정보 보호법」) and relevant laws and regulations in order to protect the freedom and rights of data subjects. Accordingly, in accordance with Article 30 of the Personal Information Protection Act, the Company establishes and discloses the following privacy policy in order to inform data subjects of the procedures and standards concerning the processing and protection of personal information and to handle related grievances promptly and smoothly.

 

This Policy applies to the Vogl and Vogl Stage services operated by the Company under the Vogl brand (hereinafter collectively the "Service").

The Company does not process the personal information of children under the age of 14.

※ Unless otherwise provided, the definitions of terms used in this Policy shall be as set out in the 'Vogl Terms of Service'.

Article 1 (Items of Personal Information Processed, Purposes and Retention Periods)

① The Company collects the following minimum personal information for purposes such as the provision of various services.

  1. Personal information is collected through information directly entered or linked by the user in the course of membership registration and use of the Service, information directly entered by the data subject in the course of submitting an inquiry, and information automatically generated and collected in the course of using the Service.

  2. If a user does not consent to the collection and use of personal information, membership registration and the smooth use of the Service may be difficult.

1. Vogl Service

 

Items Processed

Details

Purpose of Processing

Processing and Retention Period

Legal Basis

Member information

  • Email registration: email address, password, nickname

  • Social login (Google): Access Token, name, profile picture, email address, ID, native language

  • Social login (Apple)

  • Required: Access Token, name, ID, native language

  • Optional email address

  • Social login (LinkedIn): Access Token, name, picture, email address

Membership registration and provision of the Service

Until 10 days after withdrawal (recoverable by logging in again), and completely deleted thereafter

Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract)

Subscription and payment/refund history

  • Subscription information: subscription start date, cancellation date, renewal date, refund date, receipt PDF

  • Payment information: transaction ID, payment status, date and time of payment, tax information, final payment amount, email address, billing country, purchased product information, receipt URL, invoice information

  • For card payments: card brand, last 4 digits of the card number, expiration date

  • For Paypal payments: Paypal account

Processing of recurring payments and refunds

Until 5 years after withdrawal (compliance with laws and regulations)

Article 6 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce (「전자상거래법 시행령」)

Conversation records

Voice, transcribed text, translation drafts and meeting minutes summaries generated in Quick Chat and Online Meeting

Provision of the Service and improvement of service quality; use, reproduction, modification and distribution of Translation Output generated by users for research purposes relating to the operation, improvement and promotion of the Company's services and the development of new services

Retained permanently after anonymization

Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject)

Custom Assistant input and stored items

  • Required: name, field of use, Dataset title

  • Optional: English name, keywords, links to custom materials (including keywords generated from URLs such as LinkedIn profiles/YouTube/websites), uploaded files

Creation of Datasets and application to translation

Destroyed immediately after withdrawal (LinkedIn: destroyed after 3 months)

Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject)

Inquiry records

Records of inquiries and CS handling, and personal information provided by the inquirer (contact details, email information, etc.)

  1. Flitto Customer Support Center inquiries

  1. Required: email address, name of the person in charge, company name, inquiry type, content of inquiry

  2. Optional: telephone number, attachments

  1. Vogl Customer Support Center inquiries

  1. Service usage inquiries (Online Meeting / Quick Chat / Custom Assistant / plan management / inquiries on the use of Webex)

  1. [Required] email address, detailed inquiry type, content of inquiry

  2. [Optional] telephone number, platform in use, attachments

  1. Business inquiries

  1. [Required] service of inquiry (Vogl / Vogl Stage / Vogl Zone / other), email address, name (person in charge), how you heard about us, content of inquiry

  2. [Optional] company name, telephone number,
    attachments

  3. Additional items by service of inquiry

  1. Vogl Stage: [Required] inquiry type (conference use / corporate and institutional use / public and educational institution use / partnership)

  2. Vogl Zone: [Required] inquiry type (adoption / partnership / use / other)

  3. Vogl, other: no additional items

  1. Error reports

  1. [Required] email address, whether the email is registered with Vogl, content of inquiry

  2. [Optional] device used to access Vogl, telephone number, attachments

Handling of user inquiries

Until 3 years after withdrawal

Article 6, Paragraph 1, Subparagraph 4 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce

Non-member guest voice and language information

Voice and language information

Provision of the Service to non-members

Encrypted and then used for the transcription and translation of the conversation, and destroyed immediately upon the end of the conversation

Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract)


2. Vogl Stage Service

 

Items Processed

Details

Purpose of Processing

Processing and Retention Period

Legal Basis

Service inquiries

  • Required: email address, name of the person in charge, company name, how you heard about us, inquiry type, telephone number, content of inquiry

  • Optional: attachments

Receipt of and response to customer inquiries, service guidance

3 years after completion of processing the inquiry

Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject)

Member account information

Account information created and issued by the Company in accordance with the Individual Agreement (email address, password)

Identification of members and provision of the Service

Until termination of the service agreement and completion of the withdrawal process

Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract)

Conversation records

Voice, transcribed text and translation results generated in an online space (Room)

Provision of real-time interpretation and translation services and improvement of service quality

Anonymized immediately upon collection and stored in a non-decryptable manner

Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject)

Non-member guest voice and language information

Voice and language information (no personally identifiable information is collected)

Provision of the Service to non-members

Encrypted and then used for the transcription and translation of the conversation, and destroyed immediately upon the end of the conversation

Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract)


3. Personal Information Collected Automatically

In the course of using the Service, the following information is automatically generated and collected through cookies and the like. For details, please refer to Articles 7 and 8.

 

Items

Purpose of Collection

Retention Period

Service usage records, access logs, device information, cookies, behavioral information

Analysis and improvement of usage statistics for the enhancement of service quality, error analysis, provision of customized services

In accordance with the retention period for each solution under Articles 7 and 8


② However, in the cases falling under the following grounds, the Company processes and retains personal information until the relevant ground or period ends.

  1. Operation of member services

  1. Where an investigation or inquiry due to a violation of relevant laws and regulations is under way, until the conclusion of that investigation or inquiry

  2. Where claims and obligations arising from use of the Service remain outstanding, until the settlement of those claims and obligations

  1. Provision of the Service and processing of payments (retention under relevant laws and regulations)

 

Item

Retention Period

Basis for Retention

Records concerning contracts or withdrawal of subscription, etc.

5 years

Article 6, Paragraph 1, Subparagraph 2 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce

Records concerning payment of consideration and the supply of goods, etc.

5 years

Article 6, Paragraph 1, Subparagraph 3 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce

Records concerning consumer complaints or dispute resolution

3 years

Article 6, Paragraph 1, Subparagraph 4 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce

Records concerning labeling and advertising

6 months

Article 6, Paragraph 1, Subparagraph 1 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce


Article 2 (Destruction of Personal Information)

① When personal information becomes unnecessary, such as upon the lapse of the retention period or the achievement of the purpose of processing, the Company destroys such personal information without delay upon obtaining the approval of the Chief Privacy Officer.

② Where personal information must continue to be retained under other laws and regulations even though the retention period consented to by the data subject has elapsed or the purpose of processing has been achieved, such personal information shall be transferred to a separate database (DB) or retained in a different storage location.

③ The procedures and methods for the destruction of personal information are as follows.

  1. Upon the lapse of 10 days after withdrawal, personally identifiable information (email, nickname, identifying information in voice data, etc.) is completely deleted from the database and backups.

  2. Payment/subscription information is deleted after the statutory retention period has elapsed.

  3. The voice and language information of non-member guests is deleted immediately upon the end of the conversation.

  4. Information in the form of electronic files is deleted using technical methods that make the records irreproducible, and personal information printed on paper is destroyed by shredding with a shredder or by incineration.

Article 3 (Provision of Personal Information to Third Parties)

① The Company processes the personal information of data subjects within the scope of the purposes of processing specified in Article 1, and does not provide it to third parties beyond the original scope of purposes without the consent of the data subject.

② However, in the following cases, the Company may provide personal information to third parties without the consent of the data subject.

  1. Where there are special provisions in statutes or where it is unavoidable in order to comply with legal obligations

  2. Where an investigative agency makes a request for investigative purposes in accordance with the procedures and methods prescribed by statutes

  • Legal basis: Article 18, Paragraph 2, Subparagraph 2 of the Personal Information Protection Act and Article 215 of the Criminal Procedure Act (「형사소송법」)

  • Recipients: the competent police agency and prosecutors' office

  • Items provided: information within the scope requested

Article 4 (Entrustment of Personal Information Processing and Overseas Transfer)

① Pursuant to Article 26 (Restrictions on Processing of Personal Information Following Business Entrustment) and Article 28-8 (Overseas Transfer of Personal Information) of the Personal Information Protection Act, the Company entrusts the processing of personal information to domestic and overseas companies (including overseas transfer) as follows, in order to perform the data subject's service agreement and to enhance convenience.

1. Domestic Entrustment of Processing


Entrusted Company

Content of the Entrusted Work

Related Service

Stibee Inc.

Sending emails for marketing purposes, managing mailing lists

Vogl Stage


2. Overseas Entrustment of Processing and Transfer

 

Entrusted Company

Content of the Entrusted Work

Items Entrusted/Transferred

Country of Transfer / Timing and Method

Retention and Use Period

Security Measures

Related Service

Paddle, Inc.

(3811 Ditmars Blvd, #1071 Astoria, New York, 11105-1803, USA)

Payment processing

Payment information (credit card information, payment amount, recurring payment/refund history)

United States, EU / remote transmission over an encrypted communications network (SSL) each time the user uses the payment function

Until 5 years after withdrawal

GDPR compliance, data encryption

Vogl

RevenueCat, Inc

(1032 E Brandon Blvd #3003 Brandon, Florida, 33511, USA)

Payment processing

Subscription information (subscription start date, cancellation date, renewal date, refund date, receipt PDF)

United States, EU / remote transmission over an encrypted communications network (SSL) when the user registers, renews or cancels a subscription or when payment history is generated

Until 5 years after withdrawal

GDPR compliance, data encryption

Vogl

Amazon Web Services, Inc.

(410 Terry Avenue North, Seattle, WA 98109-5210, USA)

Operation of IT infrastructure for the provision of the Service, cloud server management and data storage

Service usage records, membership registration information (email, etc.), log data and device information

United States (however, the actual data storage is located in the AWS Seoul Region) / remote transmission over an encrypted communications network (HTTPS/TLS) at the time of use of the Service

Until withdrawal of membership or termination of the entrustment agreement

Compliance with ISO 27001/27017/27018 and SOC 1/2/3 certifications, data encryption

Vogl

Zendesk, Inc.

(989 Market St, San Francisco, CA 94103, USA / privacy@zendesk.com)

Customer support response, CS history management and provision of technical support services

Records of support inquiries (content of inquiry, attachments, etc.), email address, service usage records

United States and others / remote transmission over an encrypted communications network (SSL/TLS) at the time of a support inquiry

Until withdrawal of membership or termination of the entrustment agreement

Compliance with SOC 2 Type II and ISO 27001 certifications, data access control and encryption

Vogl, Vogl Stage


② When entering into an entrustment agreement, the Company specifies in documents such as the agreement matters concerning the prohibition of processing personal information for purposes other than performing the entrusted work, technical and administrative protective measures, restrictions on sub-entrustment, management and supervision of the entrustee, and liability including damages, and supervises whether the entrustee processes personal information safely.

③ Data subjects may refuse the overseas transfer of their personal information. However, if you refuse the transfer, your use of the Service may be restricted. If you do not wish the transfer to take place, please contact the Customer Support Center (support@vogl.ai).

④ Where the content of the entrusted work or the entrustee changes, the Company shall disclose this without delay through this Privacy Policy.

Article 5 (Safeguards for Personal Information)

In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following technical, administrative and physical measures to ensure the safety of personal information.

  1. Encryption of personal information : the personal information of data subjects (including voice data and translation drafts) is transmitted via the TLS (HTTPS) protocol, and passwords and payment information are encrypted and stored. The voice and language information of non-member guests is encrypted and then destroyed immediately upon the end of the conversation.

  2. Access restriction : access to personal information is controlled through the granting, modification and revocation of access rights to the database system that processes personal information, and unauthorized access from outside is controlled using an intrusion blocking system. Access rights to personal information are granted on a limited basis only to the personnel in charge (backend developers, the Operations/CS team, the Chief Privacy Officer, etc.) in accordance with the principle of least privilege.

  3. Regular security inspections : security programs are installed and inspected periodically in order to prevent the leakage and damage of personal information by hacking, computer viruses and the like, and anomalies in payment/subscription/conversation events are detected through regular security inspections conducted at least once a year.

Article 6 (Rights and Obligations of Data Subjects and Their Legal Representatives and How to Exercise Them)

① Data subjects may exercise the following rights relating to the protection of personal information against the Company at any time (hereinafter the "exercise of rights").

  1. Request for access to personal information

  2. Request for correction where there is an error or the like

  3. Request for deletion

  4. Request for suspension of processing

  5. Request for withdrawal of consent

② The exercise of rights may be carried out, in accordance with the Enforcement Decree of the Personal Information Protection Act (「개인정보 보호법 시행령」), through the Customer Support Center (support@vogl.ai) by means such as in writing or by email, and the Company shall process the request within 10 days of its receipt. Where there is a legitimate ground on which the request may be refused under the laws and regulations relating to the protection of personal information, the Company shall inform the data subject of that ground.

③ The exercise of rights may also be carried out through an agent, such as the data subject's legal representative or a person duly authorized by the data subject. In such case, a power of attorney in the form of Annexed Form No. 11 under the Notice on Methods of Processing Personal Information (「개인정보 처리 방법에 관한 고시」) must be submitted.

④ Where a data subject requests the correction or deletion of errors in personal information, the Company shall not use or provide such personal information until the correction or deletion is completed.

⑤ A data subject's right to request access to and suspension of the processing of personal information may be restricted under Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.

⑥ Where other statutes specify that the personal information is subject to collection, the deletion of such personal information may not be requested.

⑦ The Company verifies whether the person exercising the rights is the data subject himself or herself or a duly authorized agent.

Article 7 (Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof)

① In order to provide users with individually customized services and to analyse and improve usage statistics for the enhancement of service quality, the Company uses 'cookies', which store usage information and retrieve it from time to time.

② The cookies in use in the Service are as follows.

 

Cookie Name

Provider

Purpose

Description

\_clck

Microsoft Clarity

Analytics/statistics

Recognizes returning visitors and retains settings.

\_clsk

Microsoft Clarity

Analytics/statistics

Aggregates the activity of a single session into one record.

CLID

Microsoft Clarity

Analytics/statistics

Identifies whether Clarity is being used for the first time across sites.

MUID

Microsoft

Analytics/statistics

Assigns a unique browser ID, which is shared across Microsoft sites. Used for performance measurement, analytics and advertising tracking.


③ When a data subject accesses the service website, a cookie notice banner is displayed, and clicking the "Confirm" button is deemed to constitute consent to the collection of cookies.

④ Data subjects have the option as to the installation of cookies and may allow or refuse cookies, or delete collected cookies, through the settings of their web browser or mobile device. The methods of blocking and deleting cookies for each platform you use are as follows, and the methods may differ depending on the platform version. Other web browsers not listed here (e.g. Firefox, Opera) also provide cookie setting functions.

 

Platform

Method of Blocking/Deletion (Path)

Chrome

[Delete] Web browser settings > Privacy and security > Delete browsing data

Edge

[Delete] Web browser settings > Cookies and site permissions > Manage and delete cookies and site data

Safari

[Block] Preferences > 'Prevent cross-site tracking' and 'Block all cookies'

Firefox

[Settings] Settings > Privacy & Security > Cookies and Site Data

Android

[Block] Settings > Security and privacy > More privacy settings > turn off 'Android personalization service'

[Delete] Settings > Security and privacy > More privacy settings > Ads > Delete advertising ID

iOS

[Block] Settings > Privacy > Apple Advertising > turn off the 'Personalized Ads' switch


⑤ When using a web browser (PC/mobile), you may use the Service in an environment that does not permit the collection of cookies by accessing it via the following paths.

 

Platform

Method of Use (Path)

Chrome

Select the '⋮' icon at the top right of the web browser > New Incognito window (Windows: Ctrl+Shift+N / Mac: Command+Shift+N)

Edge

Select the '⋮' icon at the top right of the web browser > New InPrivate window (Windows: Ctrl+Shift+N / Mac: Command+Shift+N)

Chrome (mobile web)

Select the '⋮' icon at the top right of the mobile browser > New Incognito tab

Safari (mobile web)

Mobile device Settings > Safari > Advanced > 'Block All Cookies'

Samsung Internet (mobile web)

Select the 'Tabs' icon at the bottom of the mobile browser > turn on Secret mode > Start


⑥ If the storage of cookies is refused, difficulty may arise in using some services.

Article 8 (Collection and Use of Behavioral Information and Refusal Thereof)

① In the course of the use of the Service, the Company directly collects and uses users' 'behavioral information' in order to provide users with optimized customized services and benefits, online customized advertising and the like.

 

Advertising business operator collecting and processing behavioral information

Google (Analytics, Firebase)

Items of behavioral information collected

Advertising identifiers: 'device identifiers' randomly assigned to mobile phones (meaning Device ID, AAID (Advertising ID) on Android OS, and IDFA (Identifier For Advertisers) on iOS), and users' app visit and usage history

Method of collection

Automatically collected and transmitted when the user runs and uses the app

Purpose of collection

Provision of customized advertising based on users' interests, analysis of error information arising during use of the Service

Matters concerning the retention, use and destruction of behavioral information

Collected behavioral information is retained and used for up to 2 months from the date of collection in accordance with the settings of the service analytics solution, and is automatically destroyed by the system once that period has elapsed. For details, please refer to the privacy policy of the advertising business operator (Google) (https://policies.google.com/privacy) and its data retention guidance (https://support.google.com/analytics/answer/7667196?hl=ko).


Advertising business operator collecting and processing behavioral information

Microsoft (https://clarity.microsoft.com/)

Items of behavioral information collected

How users interact with the website

Method of collection

Automatically collected in real time using cookies when the user accesses and uses the website

Purpose of collection

Improvement of usability and provision of user-customized services

Matters concerning the retention, use and destruction of behavioral information

Collected behavioral information is retained and used for the periods set out below for each type of information in accordance with the settings of the service analytics solution, and is automatically destroyed by the system once that period has elapsed. For details, please refer to the data retention policy of the advertising business operator (Microsoft) (https://learn.microsoft.com/en-us/clarity/setup-and-installation/data-retention) and the Clarity Terms of Use (https://clarity.microsoft.com/terms ).

  • Click Data: 13 months

  • Playback Data: 30 days

  • Labeled or favorited sessions: 13 months


② The above behavioral information is information automatically generated and collected on the basis of cookies, and users may refuse the collection of cookies or delete collected cookies in accordance with the methods set out in Article 7, Paragraphs 4 and 5.

Article 9 (Compliance with Laws)

The Company processes personal information in compliance with relevant laws and regulations, including the Personal Information Protection Act of the Republic of Korea.

Article 10 (External Links)

This Privacy Policy applies only to the services of the Company. Where a user accesses an external website via a link while using the Service, the Company shall not be responsible for the protection of personal information on that website, even if the Company provided that link. Please check the privacy policy of the external website before using it.

Article 11 (Chief Privacy Officer and Department in Charge)

① The Company designates a Chief Privacy Officer and a department in charge as set out below, in order to take overall responsibility for work relating to the processing of personal information and to ensure data subjects' right to informational self-determination, handle complaints and provide remedies for damage.

Chief Privacy Officer

 

Category

Details

Name

Jungsoo Lee

Position

CEO

Email

help@flitto.com


Privacy Department

 

Category

Details

Department

Operations Team

Person in charge

Jingu Kim

Email

privacy@flitto.com


② Data subjects may direct to the Chief Privacy Officer and the department in charge any matters relating to the protection of personal information, the handling of complaints, remedies for damage and the like that arise while using the Company's services. The Company responds to and handles data subjects' inquiries sequentially within 10 days.

Article 12 (Remedies for Infringement of Data Subjects' Rights)

In order to obtain remedies for infringement of personal information, data subjects may apply to the Personal Information Dispute Mediation Committee, the Privacy Infringement Report Center of the Korea Internet & Security Agency and the like for dispute resolution, consultation or the like. For other reports of and consultations on infringement of personal information, please contact the agencies below.

  1. Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)

  2. Privacy Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)

  3. Cyber Investigation Division, Supreme Prosecutors' Office: 1301 (no area code) (http://www.spo.go.kr )

  4. Cyber Investigation Bureau, Korean National Police Agency: 182 (no area code) (http://ecrm.police.go.kr )

Article 13 (Amendment of the Privacy Policy)

① The content of this Policy shall be posted on the service screen or announced by other means, and shall take effect with respect to all users who have agreed to this Policy.

② The Company may amend this Policy in compliance with relevant laws and regulations. In the event of an amendment, the Company shall give notice to users by an announcement within the Service or by email at least 7 days before the effective date, and shall give notice 30 days in advance of any amendment that is unfavourable to users.

③ Where a user does not express refusal by the effective date after the Company has announced the changes under this Article, the user shall be deemed to have agreed to the changes. Refusal may be expressed through the Customer Support Center (support@vogl.ai).

④ In the case of an unfavourable amendment, users may expressly choose whether to consent, and if consent is refused, use of the Service may be restricted.

⑤ The amended Policy shall be announced in accordance with Paragraph 1 and shall take effect from the effective date.

Amendment History of the Privacy Policy

Version

Effective Date

Key Changes

v1.0

September 28, 2026

Consolidated enactment of the Chat Translation and Live Translation Privacy Policies


Date of Notice and Effective Date

  • Date of Notice : September 21, 2026

  • Effective Date : September 28, 2026

Upon the entry into force of this Policy, the previous 'Flitto Chat Translation Privacy Policy' and 'Flitto Live Translation Privacy Policy' are consolidated into and replaced by this Policy.

Flitto, Inc. (hereinafter referred to as the "Company") establishes and publicly discloses this Privacy Policy as follows, in order to protect the personal information of data subjects pursuant to Article 30 of the Personal Information Protection Act and to handle related grievances promptly and smoothly.

This Policy applies to the Live Translation service (hereinafter referred to as the "Service") operated by the Company. The Company does not process the personal information of children under the age of 14.


Article 1 (Purposes of Processing, Items Collected, and Retention Periods)

The Company processes personal information for the following purposes. Personal information being processed shall not be used for purposes other than those stated below. If the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.

1. Service Inquiries (Zendesk)

Personal information is collected for the purpose of receiving and responding to customer inquiries and providing service guidance.

Inquiry Channel: https://support.flitto.com/hc/ko/requests/new?ticket_form_id=28554198999449


Category

Items Collected

Retention Period

Required

Email address, Name (contact person/title and position), Company name, Phone number

2 years after inquiry resolution


2. Automatically Collected Personal Information

During the use of the Company's Service, the following information is automatically generated and collected through cookies. This information is used for the purpose of usage statistics analysis and service quality improvement. For details, please refer to Article 7.


Cookie Name

Provider

Items Collected

Purpose of Collection

_clck

Microsoft Clarity

Visitor identification information, settings values

Recognizing returning visitors and maintaining settings

_clsk

Microsoft Clarity

Session activity records

Aggregating activities within a single session into one record

CLID

Microsoft Clarity

Browser identification information

Identifying whether Clarity has been used across sites

MUID

Microsoft

Unique browser ID

Performance measurement, analysis, and advertising tracking


3. Collection Methods

  • Direct input: Data subjects enter information directly on the "Contact Us" page of the Service website.

  • Automatic collection: Automatically generated and collected through cookies during the use of the Service.


4. Retention of Personal Information Pursuant to Applicable Laws

The Company retains personal information in accordance with applicable laws as follows:


Item

Retention Period

Legal Basis

Records relating to consumer complaints or dispute resolution

3 years

Article 6 of the Act on Consumer Protection in Electronic Commerce, Etc. and Article 6 of its Enforcement Decree


Article 2 (Procedures and Methods for Destruction of Personal Information)

1. Destruction Procedures

When the retention period for personal information has expired, or the purpose of processing has been achieved, rendering the personal information unnecessary, the Company shall obtain approval from the Personal Information Protection Officer and destroy the relevant personal information without delay.

However, where retention is required under other applicable laws, the information shall be preserved by transferring it to a separate database (DB) or storing it in a different storage location for the applicable retention period.

2. Destruction Methods

  • Electronic files containing personal information shall be deleted using technical methods that render the records unrecoverable.

  • Personal information printed on paper shall be shredded using a shredder or destroyed by incineration.


Article 3 (Provision of Personal Information to Third Parties)

The Company processes personal information of data subjects within the scope of purposes specified in Article 1 and does not provide personal information to third parties beyond the original scope of purpose without the consent of the data subject.

However, personal information may be provided to third parties without the consent of the data subject in the following cases:

  1. Where there are specific provisions in other laws or where it is unavoidable to comply with statutory obligations;

  2. Where an investigative agency makes a request in accordance with the procedures and methods prescribed by law for the purpose of investigation.


Article 4 (Overseas Transfer and Entrustment of Personal Information)

The Company entrusts the processing of personal information and transfers it overseas as follows, pursuant to Article 26 (Entrustment of Business) and Article 28-8 (Overseas Transfer) of the Personal Information Protection Act, for the fulfillment of the service usage agreement and enhancement of user convenience.


Entrusted Entity

Description of Entrusted Business

Items Entrusted/Transferred

Destination Country / Timing and Method

Retention and Usage Period


Security Measures



Zendesk, Inc. (privacy@zendesk.com)

Customer consultation response, CS history management and technical support services

Consultation inquiry details (inquiry content, attachments, etc.), email address, service usage records

United States / Transmitted remotely via encrypted communication network (HTTPS/TLS) at the time of inquiry

Until membership withdrawal or termination of the entrustment agreement

SOC 2 Type II and ISO 27001 certification compliance, data access control and encryption


When executing an entrustment agreement, the Company specifies in the contractual documents the prohibition of processing personal information beyond the scope of the entrusted business, technical and administrative protective measures, restrictions on re-entrustment, management and supervision of the entrusted party, liability for damages, and other relevant matters, and supervises whether the entrusted party processes personal information safely.

Users may refuse the overseas transfer of personal information. However, if the transfer is refused, the use of the Service may be limited. If you do not wish for the transfer, please contact us through the Customer Center.

Any changes in the content of the entrusted business or the entrusted party shall be promptly disclosed through this Privacy Policy.


Article 5 (Measures to Ensure the Security of Personal Information)

The Company takes the following technical, administrative, and physical measures necessary to ensure security in accordance with Article 29 of the Personal Information Protection Act:

  1. Encryption of personal information: Personal information of data subjects is encrypted for storage and management. Data is transmitted securely using TLS (HTTPS) protocol.

  2. Access control: The Company controls access to database systems that process personal information by granting, modifying, and revoking access rights; controls unauthorized access from external sources using intrusion prevention systems; and grants access rights to personal information only to the relevant personnel in charge based on the principle of least privilege.

  3. Regular security inspections: Security programs are installed and periodically inspected to prevent the leakage and damage of personal information caused by hacking, computer viruses, and other threats.


Article 6 (Rights, Obligations, and Methods of Exercise for Data Subjects and Legal Representatives)

1. Rights of Data Subjects

Data subjects may exercise the following rights relating to personal information protection against the Company at any time:

  1. Right to request access to personal information

  2. Right to request correction in the case of errors, etc.

  3. Right to request deletion

  4. Right to request suspension of processing

  5. Right to withdraw consent

2. Methods of Exercising Rights

The above rights may be exercised by contacting the Company's Customer Center (ctlt@flitto.com) in writing, by email, or by other methods. The Company shall process such requests within 10 days of receipt. However, where there are legitimate grounds under personal information protection-related laws for refusing a request, the Company shall inform the data subject of such grounds.

3. Exercise Through a Representative

The exercise of rights may be carried out through a legal representative of the data subject or an authorized agent. In such cases, a power of attorney in the form prescribed in Appendix No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.

Where a data subject has requested correction or deletion of errors in personal information, the Company shall not use or provide the relevant personal information until the correction or deletion has been completed.


Article 7 (Matters Concerning the Installation, Operation, and Rejection of Automatic Personal Information Collection Devices)

1. Purpose of Using Cookies

The Company uses cookies solely for the purpose of usage statistics analysis and improvement to enhance service quality.


2. Cookies in Use


Cookie Name

Provider

Purpose

Description

_clck

Microsoft Clarity

Analytics/Statistics

Recognizes returning visitors and maintains settings.

_clsk

Microsoft Clarity

Analytics/Statistics

Aggregates activities within a single session into one record.

CLID

Microsoft Clarity

Analytics/Statistics

Identifies whether Clarity has been used across sites.

MUID

Microsoft

Analytics/Statistics

Assigns a unique browser ID, shared across Microsoft sites. Used for performance measurement, analysis, and advertising tracking.


3. Consent to Cookie Collection

When data subjects access the Service website, a cookie usage notification banner is displayed. Clicking the "Confirm" button is deemed as consent to cookie collection.


4. How to Refuse Cookie Settings

Data subjects have the option to accept or refuse the installation of cookies by configuring their web browser settings:

  • Chrome: Settings → Privacy and Security → Cookies and other site data

  • Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data

  • Safari: Preferences → Privacy → Cookies and website data

  • Firefox: Settings → Privacy & Security → Cookies and site data


Article 8 (Personal Information Protection Officer and Responsible Department)

The Company designates the following Personal Information Protection Officer to oversee all matters related to the processing of personal information, to be responsible for and ensure the protection of data subjects' right to self-determination regarding their personal information, and to handle complaints and remediate damages.


Personal Information Protection Officer


Category

Details

Name

Jungsoo Lee

Title

CEO

Email

help@flitto.com


Personal Information Protection Department


Category

Details

Department

Operations Team

Contact Person

Jingu Kim

Email

privacy@flitto.com


Users may direct all personal information protection-related inquiries, complaints, and requests for damage remediation arising from the use of the Company's Service to the Personal Information Protection Officer and the responsible department. The Company shall respond to and process users' inquiries without delay.


Article 9 (Remedies for Infringement of Rights of Data Subjects)

Data subjects may apply for dispute resolution, consultation, or other remedies to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency (KISA) Personal Information Infringement Report Center, or other relevant organizations. For reporting and consulting on other personal information infringement matters, please contact the following organizations:

  1. Personal Information Dispute Mediation Committee: (No area code) 1833-6972 (www.kopico.go.kr)

  2. Personal Information Infringement Report Center: (No area code) 118 (privacy.kisa.or.kr)

  3. Supreme Prosecutors' Office Cyber Investigation Division: (No area code) 1301 (Supreme Prosecutors' Office)

  4. National Police Agency Cyber Bureau: (No area code) 182 (ECRM – Cybercrime Reporting System)

Pursuant to Articles 35 (Access to Personal Information), 36 (Correction and Deletion of Personal Information), and 37 (Suspension of Processing of Personal Information) of the Personal Information Protection Act, a person who has suffered an infringement of rights or interests due to a disposition or omission by a public institution in response to a request by the data subject may file an administrative appeal in accordance with the Administrative Appeals Act.


Article 10 (Changes to the Privacy Policy)

  1. This Privacy Policy shall be posted on the Service screen or made available through other means, and shall take effect for all users who have consented to this Policy.

  2. The Company may amend this Policy in compliance with applicable laws. In the event of an amendment, users shall be notified at least 7 days prior to the effective date through an in-service notice or by email. For changes that are disadvantageous to users, notice shall be given at least 30 days in advance.

  3. After the Company posts the amended matters pursuant to this Article, if a user does not express an intention to refuse by the effective date, the user shall be deemed to have consented to the amended matters. Users may express their intention to refuse through the Customer Center (ctlt@flitto.com).

  4. In the case of changes that are disadvantageous, users may expressly choose whether or not to consent. If consent is refused, the use of the Service may be limited.

  5. The amended terms shall be posted in accordance with Paragraph 1 and shall take effect from the effective date.


Privacy Policy Amendment History

Version

Effective Date

Key Changes

v1.0

October 1, 2025

Initial enactment


Addendum

This Policy shall take effect from [August 6, 2026].

Article 1 (Purpose)

Flitto Inc. (hereinafter referred to as the "Company") establishes and implements this Privacy Policy to protect the personal information of its users and to comply with relevant laws and regulations (such as the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.).

This Policy stipulates the procedures for the processing of personal information that is collected, used, stored, and deleted when using the Live Translation service (hereinafter referred to as the "Service").

※ Unless otherwise defined, the definitions of terms used in this Policy shall be in accordance with those set forth in the 'Terms and Conditions of Service'.

Article 2 (Personal Information Collected and Method of Collection)

  1. Items Collected:

    1. Upon Membership Registration:

      • Email Registration: Email address, password, nickname.

    2. During Service Use:

      • Payment Information: Credit card information and payment-related records.

      • Custom Assistant: User-configured settings (field, job/purpose, dataset).

      • Conversation History: Text, voice, and draft translations from the online space (for members only, stored after anonymization for translation quality improvement).

      • Inquiry History: Email address, content of inquiries, and CS handling records (retained for a certain period for service improvement).

    3. Non-member Guests:

      • When participating via a Host's invitation link, only language information is collected through a simplified consent to personal information processing ("I Agree" click).

      • No personally identifiable information is collected.

  2. Method of Collection:

    • Information is collected through direct input and linkage by the user during membership registration and login.

Article 3 (Purpose of Use of Personal Information)

  1. Member Identification and Account Management: Member authentication, account consolidation, withdrawal processing.

  2. Service Provision: Providing real-time translation and customized glossary functions.

  3. Payment Processing: Subscription payment, refunds, payment error handling.

  4. Quality Improvement: Enhancing translation quality through anonymized conversation logs and meeting summaries.

  5. Customer Support: Responding to inquiries, service improvement.

Article 4 (Retention and Destruction of Personal Information)

  1. Retention Period:

    • Member Information: Retained for up to ten (10) days after withdrawal (allowing for account recovery upon re-login) and then completely deleted.

    • Subscription/Payment/Refund Records: 5 years after withdrawal (for compliance with the Act on Consumer Protection in Electronic Commerce, etc., and accounting evidence).

    • User Inquiry History: 2 years after withdrawal.

    • Member's Logs and Voice Data: Retained indefinitely after anonymization (for the purpose of translation quality improvement).

    • Non-member Language Information: Destroyed immediately after achieving the purpose of service use, following encryption.

  2. Destruction Procedure:

    • Ten (10) days after withdrawal, personally identifiable information (email, nickname, identifiers in voice data, etc.) is completely deleted from the database and backups.

    • Payment/subscription information is deleted after the legally mandated retention period.

    • The voice and language information of non-member Guests is deleted immediately upon the conclusion of the conversation.

    • Electronic data is deleted in an irrecoverable manner; physical records are shredded.

  3. If matters are not defined in the preceding paragraphs, or if the defined content conflicts with a separate contractual document agreed upon between the Company and the client, the separate contractual document shall prevail.

Article 5 (Provision of Personal Information to Third Parties)

  1. The Company shall not provide personal information to third parties without the user's consent.

  2. In the event of a request from law enforcement agencies in accordance with legal statutes, relevant information may be provided.

  3. In the case of non-member Guests, as no personally identifiable information is collected, they are not subject to third-party provision.

  4. If matters are not defined in the preceding paragraphs, or if the defined content conflicts with a separate contractual document agreed upon between the Company and the client, the separate contractual document shall prevail.

Article 6 (Measures to Ensure the Security of Personal Information)

  1. Encryption: Personal information (including voice data and draft translations) is transmitted via TLS (HTTPS), and passwords and payment information are stored in an encrypted format. The voice and language information of non-member Guests is encrypted and then immediately destroyed.

  2. Access Control: Database access is managed according to the principle of least privilege. Onboarding data and conversation history can only be viewed on a limited basis by back-end developers, the operations/CS team, and the Chief Privacy Officer.

  3. Security Monitoring: Regular security checks are conducted at least once a year to detect anomalies in payment, subscription, and conversation events.

  4. If matters are not defined in the preceding paragraphs, or if the defined content conflicts with a separate contractual document agreed upon between the Company and the client, the separate contractual document shall prevail.

Article 7 (Rights of the User)

  1. The User may, when necessary, request to view, correct, or delete their personal information through the customer service center (ctlt@flitto.com).

  2. As no personally identifiable information is collected from non-member Guests, they are not eligible to make requests for viewing, correction, or deletion.

  3. The Company must process the User's request within ten (10) days of receipt and must provide the reason for any refusal.

  4. If matters are not defined in the preceding paragraphs, or if the defined content conflicts with a separate contractual document agreed upon between the Company and the client, the separate contractual document shall prevail.

Article 8 (Compliance with Laws and Regulations)

The Company processes personal information in compliance with relevant laws and regulations, including the Personal Information Protection Act of Korea, the EU's General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA) of the United States.

Article 9 (Changes to the Policy)

  1. The content of this Policy shall become effective for all members who have consented to it by being posted on the Service screen or announced through other methods.

  2. The Company may amend this Policy in compliance with relevant laws and regulations. In the event of an amendment, the Company shall notify Members thereof via an announcement within the Service or by email at least seven (7) days prior to the effective date. Amendments that are unfavorable to the Member shall be announced thirty (30) days in advance.

  3. If, after the Company has announced the amendments in accordance with this paragraph, the User does not express an intention of refusal by the effective date, the User shall be deemed to have consented to the amended terms. The intention of refusal may be expressed through the customer service center (ctlt@flitto.com).

  4. In the case of an unfavorable amendment, the User may explicitly choose whether to consent, and refusal to consent may result in restrictions on Service use.

  5. The amended Policy shall be announced in accordance with Paragraph 1 and shall take effect from the effective date.

Article 10 (Chief Privacy Officer)

  • Chief Privacy Officer: Jungsue Lee

  • Contact: ctlt@flitto.com

  • For inquiries regarding the processing of personal information, handling of related inquiries, legal issues, etc., you can expect a response within 3-5 business days.

Addendum

This Policy shall become effective on October 1, 2025.

CEO

Simon Lee

CPO

Simon Lee

Business Registration Number

215-87-72878

E-Commerce Registration Number

2014-SeoulGangnam-02858

Address

(06173) 6F, 20 Yeongdong-daero 96-gil, Gangnam-gu, Seoul, Republic of Korea

© 2026 Flitto Inc. All rights reserved.

Family site

CEO

Simon Lee

CPO

Simon Lee

Business Registration Number

215-87-72878

E-Commerce Registration Number

2014-SeoulGangnam-02858

Address

(06173) 6F, 20 Yeongdong-daero 96-gil, Gangnam-gu, Seoul, Republic of Korea

© 2026 Flitto Inc. All rights reserved.

Family site

© 2026 Flitto Inc. All rights reserved.

Flitto Business Information

Family site